ãã®çµæã¯ãã¹ã¿ãã¯ã«ããªã¢ãäœçœ®ã«äŸåããªãã³ãŒããªã©ã®åºæ¬çãªã¹ããŒã ã§ããããŸã 誰ãã䜿çšããŠããããã§ã¯ãªãããšãè£ä»ããŠããŸãã systemdã§è匱æ§æ å ±ãå ¬éããŠãã1æã«æ³šç®ãéããã¹ã¿ãã¯ã¯ã©ãã·ã¥ã®ãããªè匱æ§ããä¿è·ããããšã«ãªããšãã³ã³ãã€ã©ã«ãšã£ãŠç¶æ³ã¯ããã«æªåããŸãã ãããããã¹ãŠãããã»ã©çµ¶æçã§ã¯ãããŸããã ãã€ããªã®å€§éšåã§ã¯ãåºæ¬çãªä¿è·æ¹æ³ãå®è£ ãããŠããããã®æ°ã¯ããŒãžã§ã³ããšã«å¢å ããŠããŸãã
æ€èšŒã«ãããOSããã³ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§Ubuntu 18.04ã«æãå€ãã®ä¿è·æ¹æ³ãå®è£ ããã次ã«Debian 9ãå®è£ ãããŠããããšã瀺ãããŸãããããã©ã«ãã§ã¯ãããã±ãŒãžã®å¯åºŠãã¯ããã«é«ããªã£ãŠããŸãã
ã¯ããã«
é«å質ã®ãœãããŠã§ã¢ãæäŸããããšã¯å°é£ã§ãã å®è¡æã®éçã³ãŒãåæããã³åçåæã®ããã®èšå€§ãªæ°ã®é«åºŠãªããŒã«ãããã³ã³ã³ãã€ã©ãŒãšããã°ã©ãã³ã°èšèªã®éçºã®èããé²æ©ã«ãããããããçŸä»£ã®ãœãããŠã§ã¢ã¯äŸç¶ãšããŠãµã€ããŒç¯çœªè ã«ãã£ãŠåžžã«æªçšãããè匱æ§ã«èŠããã§ããŸãã ã¬ã¬ã·ãŒã³ãŒããå«ããšã³ã·ã¹ãã ã§ã¯ãç¶æ³ã¯ããã«æªåããŸãã ãã®ãããªå Žåãæªçšãããå¯èœæ§ã®ãããšã©ãŒãèŠã€ãããšããæ°žé ã®åé¡ã«çŽé¢ããŠããã ãã§ãªããéå®çãªãããã«æªãããšã«è匱ãªãŸãã¯ãã°ã®ããã³ãŒããç¶æããå¿ èŠãããå³æ ŒãªåŸæ¹äºææ§ãã¬ãŒã ã¯ãŒã¯ã«ãã£ãŠå¶éãããŠããŸãã
ãããã匷åæ¹æ³ãäœçšããå Žæã§ãã äžéšã®çš®é¡ã®ãšã©ãŒãé²æ¢ããããšã¯ã§ããŸãããããããã®ãšã©ãŒã®æäœãé²æ¢ãŸãã¯é²æ¢ããããšã«ãããæ»æè ã®ç掻ãããå°é£ã«ããåé¡ãéšåçã«è§£æ±ºããããšãã§ããŸãã ãã®ãããªä¿è·ã¯ãã¹ãŠã®ææ°ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§äœ¿çšãããŠããŸããããã®æ¹æ³ã¯ãã¹ã¿ãã¯ã«ããªã¢ãASLRããæ¬æ ŒçãªCFIããã³ROPä¿è·ãŸã§ãè€éããå¹çãããã³ããã©ãŒãã³ã¹ã倧ããç°ãªããŸãã ãã®èšäºã§ã¯ãããã©ã«ãæ§æã®æãäžè¬çãªLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã§äœ¿çšãããŠããä¿è·æ¹æ³ãæ€èšããåãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ããã±ãŒãžç®¡çã·ã¹ãã ãä»ããŠé åžããããã€ããªã®ããããã£ã調ã¹ãŸãã
CVEãšã»ãã¥ãªãã£
ãMost Vulnerable Applications of the YearãããMost Vulnerable Operating Systemsããªã©ã®ã¿ã€ãã«ã®èšäºãèŠãŠããŸããã éåžžã NISTããã³ãã®ä»ã®ãœãŒã¹ã®National Vulnerability DatabaseïŒNVDïŒããååŸããCVEïŒCommon Vulnerability and ExposuresïŒãªã©ã®è匱æ§ã¬ã³ãŒãã®ç·æ°ã«é¢ããçµ±èšãæäŸããŸãã ãã®åŸããããã®ã¢ããªã±ãŒã·ã§ã³ãŸãã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ãCVEã®æ°ã«ãã£ãŠã©ã³ã¯ä»ããããŸãã æ®å¿µãªãããCVEã¯åé¡ã®è¿œè·¡ããã³ããŒããŠãŒã¶ãŒãžã®éç¥ã«ã¯éåžžã«åœ¹ç«ã¡ãŸããããœãããŠã§ã¢ã®å®éã®ã»ãã¥ãªãã£ã«ã€ããŠã¯ã»ãšãã©èªã£ãŠããŸããã
äŸãšããŠãLinuxã«ãŒãã«ãš5ã€ã®æã人æ°ã®ãããµãŒããŒãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ããUbuntuãDebianãRed Hat Enterprise Linuxãããã³OpenSUSEã®éå»4幎éã®CVEã®ç·æ°ãèããŠã¿ãŠãã ããã
å³ 1
ãã®ãã£ãŒãã¯äœãæããŠãããŸããïŒ CVEãå€ããšããããšã¯ããããã£ã¹ããªãã¥ãŒã·ã§ã³ãä»ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ãããè匱ã§ããããšãæå³ããŸããïŒ çãã¯ãããŸããã ããšãã°ããã®èšäºã§ã¯ãDebianã®ã»ãã¥ãªãã£ã¡ã«ããºã ã¯ãããšãã°OpenSUSEãRedHat Linuxã«æ¯ã¹ãŠå ç¢ã§ãããããã«Debianã«ã¯CVEãå€ãããšãããããŸãã ãã ãããããã¯å¿ ãããã»ãã¥ãªãã£ã®äœäžãæå³ããããã§ã¯ãããŸãããCVEãæã£ãŠãããããšãã£ãŠãè匱æ§ãæªçšå¯èœãã©ããã¯ããããŸããã é倧床ã¹ã³ã¢ã¯ãè匱æ§ã®æªçšã®å¯èœæ§ã瀺ããŸãããæçµçã«ã¯ãæªçšå¯èœæ§ã¯ã圱é¿ãåããã·ã¹ãã ã«ååšããä¿è·ãããã³æ»æè ã®ãªãœãŒã¹ãšèœåã«å€§ããäŸåããŸãã ããã«ãCVEã¬ããŒãã®æ¬ åŠã¯ãä»ã®æªç»é²ãŸãã¯æªç¥ã®è匱æ§ã«ã€ããŠã¯äœãè¿°ã¹ãŠããŸããã CVEã®éãã¯ããœãããŠã§ã¢ã®å質ã§ã¯ãªãããã¹ãã«å²ãåœãŠããããªãœãŒã¹ããŠãŒã¶ãŒããŒã¹ã®ãµã€ãºãªã©ã®ä»ã®èŠå ã«ãã£ãŠèª¬æã§ããŸãã ãã®äŸã§ã¯ãããå€ãã®Debian CVEããDebianãããå€ãã®ãœãããŠã§ã¢ããã±ãŒãžãæäŸããŠããããšãåã«ç€ºããŠããå ŽåããããŸãã
ãã¡ãããCVEã·ã¹ãã ã¯ãé©åãªä¿è·ãäœæã§ããæçšãªæ å ±ãæäŸããŸãã ããã°ã©ã ã®ã¯ã©ãã·ã¥ã®åå ãããæ·±ãç解ããã°ããã»ã©ãå¯èœãªæäœæ¹æ³ãç¹å®ããé©åãªæ€åºããã³å¿çã¡ã«ããºã ãéçºããããšã容æã«ãªããŸãã å³ å³2ã¯ãéå»4幎éã®ãã¹ãŠã®ååžã®è匱æ§ã®ã«ããŽãªã瀺ããŠããŸãïŒ ãœãŒã¹ ïŒã ã»ãšãã©ã®CVEã¯ããµãŒãã¹æåŠïŒDoSïŒãã³ãŒãå®è¡ããªãŒããŒãããŒãã¡ã¢ãªç Žæãæ å ±æŒããïŒæµåºïŒãããã³æš©éææ Œã®ã«ããŽãªã«åé¡ãããããšã¯ããã«ããããŸãã å€ãã®CVEãããŸããŸãªã«ããŽãªã§äœåºŠãåãäžããããŠããŸãããäžè¬ã«ãåãåé¡ã幎ã ç¶ããŠããŸãã èšäºã®æ¬¡ã®éšåã§ã¯ããããã®è匱æ§ã®æªçšãé²ãããã®ããŸããŸãªä¿è·ã¹ããŒã ã®äœ¿çšãè©äŸ¡ããŸãã
å³ 2
ã¿ã¹ã¯
ãã®èšäºã§ã¯ã次ã®è³ªåã«çããŸãã
- ããŸããŸãªLinuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãšã¯äœã§ããïŒ ã«ãŒãã«ãââãã³ãŠãŒã¶ãŒç©ºéã¢ããªã±ãŒã·ã§ã³ã«ã¯ã©ã®ãããªé²åŸ¡ã¡ã«ããºã ãååšããŸããïŒ
- ããŸããŸãªãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ä¿è·ã¡ã«ããºã ã®æ¡çšã¯ãæéã®çµéãšãšãã«ã©ã®ããã«å€åããŸãããïŒ
- åãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ããã±ãŒãžããã³ã©ã€ãã©ãªã®å¹³åçãªäŸåé¢ä¿ã¯äœã§ããïŒ
- åãã€ããªã«ã¯ã©ã®ãããªä¿è·ãå®è£ ãããŠããŸããïŒ
ååžã®éžæ
ã»ãšãã©ã®å ŽåãããŠã³ããŒãæ°ã¯å®éã®ã€ã³ã¹ããŒã«æ°ã瀺ããŠããªãããããã£ã¹ããªãã¥ãŒã·ã§ã³ã€ã³ã¹ããŒã«ã«é¢ããæ£ç¢ºãªçµ±èšãèŠã€ããããšã¯å°é£ã§ããããšãããããŸãã ãã ããUnixã®äºçš®ããµãŒããŒã·ã¹ãã ã®å€§éšåãå ãïŒWebãµãŒããŒã§ã¯69.2ïŒ ã W3techããã³ãã®ä»ã®ãœãŒã¹ããã®çµ±èšã«ãããšïŒããã®ã·ã§ã¢ã¯åžžã«å¢å ããŠããŸãã ãã®ãããç§ãã¡ã®èª¿æ»ã§ã¯ã Google Cloudãã©ãããã©ãŒã ã§ããã«äœ¿çšã§ãããã£ã¹ããªãã¥ãŒã·ã§ã³ã«çŠç¹ãåœãŠãŸããã ç¹ã«ã次ã®OSãéžæããŸããã
é åž/ããŒãžã§ã³ | ã³ã¢ | æ§ç¯ãã |
---|---|---|
OpenSUSE 12.4 | 4.12.14-95.3-default | ïŒ1 SMP Wed Dec 5 06:00:48 UTC 2018ïŒ63a8d29ïŒ |
Debian 9ïŒã¹ãã¬ããïŒ | 4.9.0-8-amd64 | ïŒ1 SMP Debian 4.9.130-2ïŒ2018-10-27ïŒ |
CentOS 6.10 | 2.6.32-754.10.1.el6.x86_64 | ïŒ1 SMP Tue Jan 15 17:07:28 UTC 2019 |
CentOS 7 | 3.10.0-957.5.1.el7.x86_64 | ïŒ1 SMPé2æ1æ¥14:54:57 UTC 2019 |
Red Hat Enterprise Linux Server 6.10ïŒãµã³ãã£ã¢ãŽïŒ | 2.6.32-754.9.1.el6.x86_64 | ïŒ1 SMPæ°Žææ¥11æ21æ¥15:08:21 EST 2018 |
Red Hat Enterprise Linux Server 7.6ïŒãã€ãïŒ | 3.10.0-957.1.3.el7.x86_64 | ïŒ1 SMPæš11æ15 17:36:42 UTC 2018 |
Ubuntu 14.04ïŒTrusty TahrïŒ | 4.4.0â140-generic |
ïŒ166ã14.04.1-Ubuntu SMP 11æ17æ¥ïŒåïŒ01:52:43 UTC 20 ... |
Ubuntu 16.04ïŒXenial XerusïŒ | 4.15.0-1026-gcp | ïŒ27ã16.04.1-Ubuntu SMP Fri Dec 7 09:59:47 UTC 2018 |
Ubuntu 18.04ïŒãã€ãªããã¯ããŒããŒïŒ | 4.15.0-1026-gcp | ïŒ27-Ubuntu SMPæš12æ6æ¥18:27:01 UTC 2018 |
åæ
ããã©ã«ãã®ã«ãŒãã«æ§æãšãããã«äœ¿çšå¯èœãªåé åžããã±ãŒãžã®ããã±ãŒãžãããŒãžã£ãŒãä»ããŠå©çšå¯èœãªããã±ãŒãžã®ããããã£ã調ã¹ãŸãã ãããã£ãŠãåãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ããã©ã«ããã©ãŒã®ããã±ãŒãžã®ã¿ãèæ ®ããäžå®å®ãªãªããžããªã®ããã±ãŒãžïŒããšãã°ãDebianã®ããã¹ãããã©ãŒïŒããã³ãµãŒãããŒãã£ã®ããã±ãŒãžïŒæšæºãã©ãŒã®Nvidiaããã±ãŒãžãªã©ïŒã¯ç¡èŠããŸãã ããã«ãã»ãã¥ãªãã£ã匷åãããã«ã¹ã¿ã ã«ãŒãã«ã®ã³ã³ãã€ã«ãŸãã¯æ§æã¯èæ ®ããŸããã
ã«ãŒãã«æ§æåæ
ç¡æã®kconfigãã§ãã«ãŒã«åºã¥ãåæã¹ã¯ãªããã䜿çšããŸããã ååä»ããã£ã¹ããªãã¥ãŒã·ã§ã³ã®æšæºã®ä¿è·ãªãã·ã§ã³ãæ€èšããKernel Self-Defense Project ïŒKSPPïŒã®ãªã¹ããšæ¯èŒããŸãã åæ§æãã©ã¡ãŒã¿ãŒã«ã€ããŠãè¡š2ã«ç®çã®èšå®ã瀺ããŸãïŒãã§ãã¯ããŒã¯ã¯ãKSSPã®æšå¥šäºé ã«æºæ ãããã£ã¹ããªãã¥ãŒã·ã§ã³ã瀺ããŸãïŒçšèªã®èª¬æã«ã€ããŠã¯ã ãã¡ããåç §ããŠãã ãã ãä»åŸã®èšäºã§ã¯ããããã®ä¿è·æ¹æ³ã®æ°ãšãããããååšããªãå Žåã«ã·ã¹ãã ããããã³ã°ããæ¹æ³ã«ã€ããŠèª¬æããŸãïŒã
äžè¬ã«ãæ°ããã«ãŒãã«ã«ã¯ãããå³ããèšå®ãããã«é©çšãããŸãã ããšãã°ã2.6.32ã«ãŒãã«ã®CentOS 6.10ããã³RHEL 6.10ã«ã¯ã SMAP ãå³å¯ãªRWXã¢ã¯ã»ã¹èš±å¯ãã¢ãã¬ã¹ã©ã³ãã åãcopy2usrä¿è·ãªã©ãæ°ããã«ãŒãã«ã«å®è£ ãããéèŠãªæ©èœã®ã»ãšãã©ããããŸããã è¡šã®æ§æãªãã·ã§ã³ã®å€ãã¯ãã«ãŒãã«ã®å€ãããŒãžã§ã³ã§ã¯äœ¿çšã§ãããå®éã«ã¯é©çšãããªãããšã«æ³šæããŠãã ãã-ããã¯ãé©åãªä¿è·ã®æ¬ åŠãšããŠè¡šã«ç€ºãããŠããŸãã åæ§ã«ããã®ããŒãžã§ã³ã§æ§æãã©ã¡ãŒã¿ãŒã䜿çšã§ãããã»ãã¥ãªãã£ã®ããã«ãã®ãã©ã¡ãŒã¿ãŒãç¡å¹ã«ããå¿ èŠãããå Žåãããã¯åççãªæ§æãšèŠãªãããŸãã
çµæã解éããéã®å¥ã®ãã€ã³ãïŒæ»æ察象é åãå¢ããããã€ãã®ã«ãŒãã«æ§æã¯ãã»ãã¥ãªãã£ã®ããã«åæã«äœ¿çšã§ããŸãã ãã®ãããªäŸã«ã¯ãã¢ããããŒããškprobesãã«ãŒãã«ã¢ãžã¥ãŒã«ãããã³BPF / eBPFãå«ãŸããŸãã äžèšã®ã¡ã«ããºã ã䜿çšããŠå®éã®ä¿è·ãæäŸããããšããå§ãããŸãã䜿çšããã®ã¯ç°¡åã§ã¯ãªããæªæã®ããã¢ã¯ã¿ãŒããã§ã«ã·ã¹ãã ã«å®çããŠãããšæ³å®ããŠããããã§ãã ãã ãããããã®ãªãã·ã§ã³ãæå¹ã«ãªã£ãŠããå Žåãã·ã¹ãã 管çè ã¯äžæ£è¡çºãç©æ¥µçã«ç£èŠããå¿ èŠããããŸãã
è¡š2ã®ãšã³ããªãããã«èª¿ã¹ããšãææ°ã®ã«ãŒãã«ã«ã¯ãæ å ±æŒæŽ©ãã¹ã¿ãã¯/ããŒããªãŒããŒãããŒãªã©ã®è匱æ§ã®æªçšããä¿è·ããããã®ããã€ãã®ãªãã·ã§ã³ãçšæãããŠããããšãããããŸãã ãã ããææ°ã®äººæ°ã®ãããã£ã¹ããªãã¥ãŒã·ã§ã³ã§ãããããé«åºŠãªä¿è·ïŒ grsecurityããããªã©ïŒãã³ãŒãåå©çšæ»æã«å¯Ÿããææ°ã®ä¿è·ïŒã³ãŒãã®ã©ã³ãã åãšR ^ Xã¹ããŒã ã®çµã¿åãããªã©ïŒããŸã å®è£ ãããŠããªãããšãããããŸãã ããã«æªãããšã«ããããã®ããé«åºŠãªé²åŸ¡ã§ãããããããçš®é¡ã®æ»æããä¿è·ããããšã¯ã§ããŸããã ãããã£ãŠãã·ã¹ãã 管çè ãå®è¡æã«ãšã¯ã¹ããã€ãã®æ€åºãšé²æ¢ãæäŸãããœãªã¥ãŒã·ã§ã³ã§ã€ã³ããªãžã§ã³ããªæ§æãè£å®ããããšãéèŠã§ãã
ã¢ããªã±ãŒã·ã§ã³åæ
ãã£ã¹ããªãã¥ãŒã·ã§ã³ããšã«ããã±ãŒãžãã³ã³ãã€ã«ãªãã·ã§ã³ãã©ã€ãã©ãªã®äŸåé¢ä¿ãªã©ã®ç¹æ§ãç°ãªãããšã¯é©ãããšã§ã¯ãããŸããã é¢é£ãããã£ã¹ããªãã¥ãŒã·ã§ã³ãšäŸåé¢ä¿ã®æ°ãå°ãªãããã±ãŒãžïŒUbuntuãŸãã¯Debianã®coreutilsãªã©ïŒã«ãéãããããŸãã éããè©äŸ¡ããããã«ãå©çšå¯èœãªãã¹ãŠã®ããã±ãŒãžãããŠã³ããŒããããã®å 容ãæœåºããŠããã€ããªãã¡ã€ã«ãšäŸåé¢ä¿ãåæããŸããã ããã±ãŒãžããšã«ãäŸåããä»ã®ããã±ãŒãžã远跡ãããã€ããªããšã«äŸåé¢ä¿ã远跡ããŸããã ãã®ã»ã¯ã·ã§ã³ã§ã¯ã調æ»çµæãèŠçŽããŸãã
ååž
åèšã§ããã¹ãŠã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§361,556åã®ããã±ãŒãžãããŠã³ããŒãããããã©ã«ãã®ãã©ãŒããããã±ãŒãžã®ã¿ãæœåºããŸããã ãœãŒã¹ã³ãŒãããã©ã³ããªã©ãELFå®è¡å¯èœãã¡ã€ã«ã®ãªãããã±ãŒãžã¯ç¡èŠããŸããããã£ã«ã¿ãªã³ã°åŸã129 569åã®ããã±ãŒãžãæ®ããåèš584 457åã®ãã€ããªãã¡ã€ã«ãå«ãŸããŠããŸããã ãã£ã¹ããªãã¥ãŒã·ã§ã³éã§ã®ããã±ãŒãžãšãã¡ã€ã«ã®é åžãå³ã«ç€ºããŸãã 3ã
å³ 3
ãã£ã¹ããªãã¥ãŒã·ã§ã³ããããææ°ã®ãã®ã§ããã»ã©ãããã«å«ãŸããããã±ãŒãžãšãã€ããªãã¡ã€ã«ãå€ããªãããšãããããŸããããã¯è«ççã§ãã åæã«ãUbuntuããã³Debianããã±ãŒãžã«ã¯ãCentOSãSUSEãããã³RHELãããã¯ããã«å€ãã®ãã€ããªãã¡ã€ã«ïŒå®è¡å¯èœã¢ãžã¥ãŒã«ãšåçã¢ãžã¥ãŒã«ããã³ã©ã€ãã©ãªïŒãå«ãŸããŠããŸããããã±ãŒãžãã€ãŸããããã€ãã®ãã¡ã€ã«ãæ°ååæãããŸãïŒã ããã¯ãããã±ãŒãžéã®äŸåé¢ä¿ãèæ ®ããå Žåã«ç¹ã«éèŠã§ãã ãããã£ãŠãåäžã®ããã±ãŒãžã®ãã€ããªã®è匱æ§ã¯ããããã€ã³ããŒããããã¹ãŠã®ãã€ããªãã¡ã€ã«ã«è匱ãªã©ã€ãã©ãªã圱é¿ããã®ãšåæ§ã«ããšã³ã·ã¹ãã ã®å€ãã®éšåã«åœ±é¿ãäžããå¯èœæ§ããããŸãã åç §ãã€ã³ããšããŠãããŸããŸãªOSã®ããã±ãŒãžéã®äŸåé¢ä¿ã®æ°ã®ååžãèŠãŠã¿ãŸãããã
å³ 4
ã»ãšãã©ãã¹ãŠã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã¯ãããã±ãŒãžã®60ïŒ ã«å°ãªããšã10åã®äŸåé¢ä¿ããããŸãã ããã«ãäžéšã®ããã±ãŒãžã«ã¯ããå€ãã®äŸåé¢ä¿ããããŸãïŒ100以äžïŒã éã®ããã±ãŒãžäŸåé¢ä¿ã«ãåãããšãåœãŠã¯ãŸããŸããäºæ³ã©ããããã£ã¹ããªãã¥ãŒã·ã§ã³å ã®ä»ã®å€ãã®ããã±ãŒãžã§ããã€ãã®ããã±ãŒãžã䜿çšãããŠããããããããã®ããã€ãã®ãæ°ã«å ¥ãã®è匱æ§ã«ã¯é«ããªã¹ã¯ããããŸãã äŸãšããŠãSLESãCentos 7ãDebian 9ãããã³Ubuntu 18.04ã§æ倧æ°ã®éäŸåé¢ä¿ãæã€20åã®ããã±ãŒãžã次ã®è¡šã«ç€ºããŸãïŒåããã¯ã¹ã¯ããã±ãŒãžãšéäŸåé¢ä¿ã®æ°ã瀺ããŸãïŒã
è¡š3
èå³æ·±ãäºå®ã åæããããã¹ãŠã®OSã¯x86_64ã¢ãŒããã¯ãã£çšã«æ§ç¯ãããŠãããã»ãšãã©ã®ããã±ãŒãžã§ã¯ã¢ãŒããã¯ãã£ãx86_64ããã³x86ãšããŠå®çŸ©ãããŠããŸãããå³ã«ç€ºãããã«ããã±ãŒãžã«ã¯ä»ã®ã¢ãŒããã¯ãã£ã®ãã€ããªãå«ãŸããŠããããšããããããŸã 5ã
å³ 5
次ã®ã»ã¯ã·ã§ã³ã§ã¯ãåæããããã€ããªã®ç¹æ§ãæãäžããŸãã
ãã€ããªä¿è·çµ±èš
æäœéãæ¢åã®ãã€ããªãã¡ã€ã«ã®ä¿è·ãªãã·ã§ã³ã®åºæ¬ã»ãããæ€èšããå¿ èŠããããŸãã ããã€ãã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã«ã¯ããã®ãããªãã§ãã¯ãå®è¡ããã¹ã¯ãªãããä»å±ããŠããŸãã ããšãã°ãDebian / Ubuntuã«ã¯ãã®ãããªã¹ã¯ãªããããããŸãã 圌ã®äœåã®äŸã次ã«ç€ºããŸãã
$ hardening-check $(which docker) /usr/bin/docker: Position Independent Executable: yes Stack protected: yes Fortify Source functions: no, only unprotected functions found! Read-only relocations: yes Immediate binding: yes
ã¹ã¯ãªããã¯5ã€ã®ä¿è·æ©èœããã§ãã¯ããŸã ã
- äœçœ®ç¬ç«å®è¡å¯èœãã¡ã€ã«ïŒPIEïŒïŒã«ãŒãã«ã§ASLRãæå¹ã«ãªã£ãŠããå Žåãããã°ã©ã ããã¹ãã»ã¯ã·ã§ã³ãã¡ã¢ãªå
ã§ç§»åããŠã©ã³ãã åãå®çŸã§ãããã©ããã瀺ããŸãã
- ã¹ã¿ãã¯ä¿è·ïŒã¹ã¿ãã¯è¡çªæ»æããä¿è·ããããã«ã¹ã¿ãã¯ã«ããªã¢ãå«ãããã©ããã
- Fortify SourceïŒå®å
šã§ãªãé¢æ°ïŒããšãã°strcpyïŒãããå®å
šãªå¯Ÿå¿ãããã®ã«çœ®ãæããå®è¡æã«ãã§ãã¯ãããåŒã³åºããæ€èšŒãããŠããªã察å¿ãããã®ïŒããšãã°__memcpy_chkã§ã¯ãªãmemcpyïŒã«çœ®ãæãããã©ããã
- èªã¿åãå°çšåé
眮ïŒRELROïŒïŒå®è¡ãéå§ãããåã«åäœããå Žåã移åããŒãã«å
ã®ãšã³ããªãèªã¿åãå°çšãšããŠããŒã¯ããããã©ããã
- å³æãã€ã³ãã£ã³ã°ïŒå®è¡æãªã³ã«ãŒã¯ãããã°ã©ã ãéå§ããåã«ãã¹ãŠã®ç§»åãèš±å¯ããŸãïŒããã¯å®å šãªRELROãšåçã§ãïŒã
äžèšã®ã¡ã«ããºã ã§ååã§ããïŒ æ®å¿µãªããããããŸããã äžèšã®ãã¹ãŠã®é²åŸ¡ãåé¿ããæ¢ç¥ã®æ¹æ³ããããŸãããé²åŸ¡ãå³ããã»ã©ãæ»æè ã®æ°Žæºã¯é«ããªããŸãã ããšãã°ãPIEãšå³æãã€ã³ãã£ã³ã°ãæå¹ãªå Žåã RELROã®åé¿çãé©çšããã®ã¯å°é£ã§ãã åæ§ã«ãå®å šãªASLRãæ©èœããæªçšãäœæããã«ã¯è¿œå ã®äœæ¥ãå¿ èŠã§ãã ãã ããé«åºŠãªæ»æè ã¯ãã§ã«ãã®ãããªé²åŸ¡ã«å¯Ÿå¿ããæºåãã§ããŠããŸãã圌ããããªããšãåºæ¬çã«ãããã³ã°ãå éãããŸãã ãããã£ãŠããããã®å¯Ÿçãå¿ èŠæå°éã«ããå¿ èŠããããŸã ã
åé¡ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³å ã®ãã€ããªãã¡ã€ã«ããããã«ãã£ãŠä¿è·ãããŠããæ°ãšãããã«3ã€ã®æ¹æ³ãç¥ããããšæããŸããã
- å®è¡äžèœãããïŒ NX ïŒã¯ãã¹ã¿ãã¯ããŒããªã©ãå®è¡å¯èœã§ãªãã¯ãã®é åã§ã®å®è¡ãé²æ¢ããŸãã
- RPATH / RUNPATHã¯ãé©åãªã©ã€ãã©ãªãèŠã€ããããã«ãã€ãããã¯ããŒããŒã䜿çšããå®è¡ãã¹ã瀺ããŸãã 1ã€ç®ã¯ãçŸä»£ã®ã·ã¹ãã ã§ã¯å¿ é ã§ããæ»æè ãäžåšã®å Žåããã€ããŒããã¡ã¢ãªã«ä»»æã«æžã蟌ã¿ããã®ãŸãŸå®è¡ããããšãã§ããŸãã 2çªç®ã®ãå®è¡ãã¹ã®äžé©åãªæ§æã¯ãä¿¡é Œã§ããªãã³ãŒãã®å°å ¥ã«åœ¹ç«ã¡ãŸããããã¯ãå€ãã®åé¡ïŒ ç¹æš©ã®ãšã¹ã«ã¬ãŒã·ã§ã³ã ä»ã®åé¡ãªã© ïŒã«ã€ãªããå¯èœæ§ããããŸãã
- ã¹ã¿ãã¯è¡çªä¿è·ã¯ãã¹ã¿ãã¯ãã¡ã¢ãªã®ä»ã®é åïŒããŒããªã©ïŒãšéè€ããåå ãšãªãæ»æã«å¯Ÿããä¿è·ãæäŸããŸãã systemdã®ããŒãè¡çªã®è匱æ§ãæªçšããæè¿ã®ãšã¯ã¹ããã€ããèãããšããã®ã¡ã«ããºã ãããŒã¿ã»ããã«å«ããããšãé©åã§ããããšãããããŸããã
ãããã£ãŠããã以äžèŠåŽããããšãªããæ°åã«ç§»ããŸãããã è¡š4ãš5ã«ã¯ããããããããŸããŸãªãã£ã¹ããªãã¥ãŒã·ã§ã³ã®å®è¡å¯èœãã¡ã€ã«ãšã©ã€ãã©ãªã®åæãå«ãŸããŠããŸãã
- ã芧ã®ãšãããNXã®ä¿è·ã¯ããŸããªäŸå€ãé€ããŠã©ãã§ãå®è£
ãããŠããŸãã ç¹ã«ãUbuntuããã³Debianãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã®äœ¿çšçãäœãããšã¯ãCentOSãRHELãããã³OpenSUSEãšæ¯èŒããŠæ³šç®ã«å€ããŸãã
- ã¹ã¿ãã¯ã«ããªã¢ã¯å€ãã®å Žæãç¹ã«å€ãã«ãŒãã«ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã¯å©çšã§ããŸããã CentosãRHELãDebianãããã³Ubuntuã®æè¿ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã¯ãããã€ãã®é²æ©ãèŠãããŸããã
- DebianãšUbuntu 18.04ãé€ããã»ãšãã©ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯PIEãµããŒããäžååã§ãã
- ã¹ã¿ãã¯ã®è¡çªä¿è·ã¯ãOpenSUSEãCentos 7ãããã³RHEL 7ã§å®è£
ãäžååã§ãããä»ã«ã¯ã»ãšãã©ãããŸããã
- ææ°ã®ã«ãŒãã«ãåãããã¹ãŠã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯RELROããµããŒãããŠãããUbuntu 18.04ãå å°ããDebianã2äœã«ãªããŸããã
æ¢ã«è¿°ã¹ãããã«ããã®è¡šã®ã¡ããªãã¯ã¯ãã€ããªãã¡ã€ã«ã®ãã¹ãŠã®ããŒãžã§ã³ã®å¹³åã§ãã ãã¡ã€ã«ã®ææ°ããŒãžã§ã³ã®ã¿ãèŠããšãæ°åã¯ç°ãªããŸãïŒããšãã°ã PIEã®å®è£ ã«é¢ããDebianã®é²æç¶æ³ãåç §ããŠãã ããïŒã ããã«ãã»ãšãã©ã®ååžã§ã¯ãéåžžãçµ±èšã®èšç®æã«ãã€ããªã³ãŒãå ã®ããã€ãã®é¢æ°ã®ä¿è·ã®ã¿ããã§ãã¯ãããåæã§ã¯åŒ·åãããé¢æ°ã®çã®å²åã瀺ãããŸãã ãããã£ãŠã50åã®é¢æ°ã®ãã¡5åããã€ããªã§ä¿è·ãããŠããå Žåã0.1ã®è©äŸ¡ãä»ããŸããããã¯ã匷åãããé¢æ°ã®10ïŒ ã«çžåœããŸãã
è¡š4.å³ã«ç€ºãããŠããå®è¡å¯èœãã¡ã€ã«ã®ä¿è·ç¹æ§ 3ïŒå®è¡å¯èœãã¡ã€ã«ã®ç·æ°ã«å¯Ÿããå²åãšããŠã®å¯Ÿå¿ããæ©èœã®å®è£ ïŒ
è¡š5.å³ã«ç€ºãã©ã€ãã©ãªã®ä¿è·ç¹æ§ 3ïŒã©ã€ãã©ãªã®ç·æ°ã«å¯Ÿããå²åãšããŠã®å¯Ÿå¿ããæ©èœã®å®è£ ïŒ
é²æã¯ãããŸããïŒ ç¢ºãã«ãããŸãïŒåã ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ïŒããšãã°ã Debian ïŒã®çµ±èšãšäžèšã®è¡šããèŠãããšãã§ããŸãã å³ã®äŸãšã㊠å³6ã¯ã3ã€ã®é£ç¶ããUbuntu LTS 5ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ã®é²åŸ¡ã¡ã«ããºã ã®å®è£ ã瀺ããŠããŸãïŒã¹ã¿ãã¯è¡çªä¿è·ã®çµ±èšæ å ±ã¯çç¥ããŠããŸãïŒã ããŒãžã§ã³ããšã«ã¹ã¿ãã¯ã«ããªã¢ããµããŒããããã¡ã€ã«ãå¢ããŠããããšã«æ°ã¥ããŸãããŸããé 次ããŸããŸãå€ãã®ãã€ããªãã¡ã€ã«ãå®å šãªRELROä¿è·ãåããŠããŸãã
å³ 6
æ®å¿µãªãããããŸããŸãªãã£ã¹ããªãã¥ãŒã·ã§ã³ã®å€ãã®å®è¡å¯èœãã¡ã€ã«ã«ã¯ãäžèšã®ä¿è·ããŸã ãããŸããã ããšãã°ãUbuntu 18.04ãèŠããšãngettyãã€ããªïŒgettyã®ä»£æ¿ïŒãmkshã·ã§ã«ãšlkshã·ã§ã«ãpicolispã€ã³ã¿ãŒããªã¿ãŒãnvidia-cuda-toolkitããã±ãŒãžïŒGPUã¢ã¯ã»ã©ã¬ãŒã·ã§ã³ã¢ããªã±ãŒã·ã§ã³ïŒæ©æ¢°åŠç¿ãã¬ãŒã ã¯ãŒã¯ãªã©ïŒã®äžè¬çãªããã±ãŒãžïŒããã³klibcã確èªã§ããŸã-utilsã åæ§ã«ãmandos-clientãã€ããªïŒæå·åããããã¡ã€ã«ã·ã¹ãã ã§ãã·ã³ãèªåçã«åèµ·åã§ãã管çããŒã«ïŒãããã³rsh-redone-clientïŒrshãšrloginãåå®è£ ïŒã¯ãSUIDæš©éããããŸãããNXä¿è·ãªãã§é ä¿¡ãããŸãïŒã¹ã¿ãã¯ã«ããªã¢ïŒXorgããã±ãŒãžã®Xorg.wrapãã€ããªãªã©ïŒãªã©ãããã€ãã®suidãã€ããªã«ã¯åºæ¬çãªä¿è·ããããŸããã
ãŸãšããšçµè«
ãã®èšäºã§ã¯ãææ°ã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ã»ãã¥ãªãã£æ©èœãããã€ãåãäžããŸããã åæã®çµæãææ°ã®Ubuntu LTSãã£ã¹ããªãã¥ãŒã·ã§ã³ïŒ18.04ïŒã¯ãUbuntu 14.04ã12.04ãDebian 9ãªã©ã®æ¯èŒçæ°ããã«ãŒãã«ãåãããã£ã¹ããªãã¥ãŒã·ã§ã³ã®äžã§ãå¹³åããŠæã匷åãªOSããã³ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ä¿è·ãåããŠããããšãããããŸãããããããã¬ãã¥ãŒããCentOSãRHELãããã³OpenSUSEãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯ãããã©ã«ãã§ã¯ãããé«å¯åºŠã®ããã±ãŒãžã»ãããçºè¡ãããæè¿ã®ããŒãžã§ã³ïŒCentOSããã³RHELïŒã§ã¯ãDebianããŒã¹ã®ç«¶åä»ç€ŸïŒDebianããã³UbuntuïŒãšæ¯èŒããŠã¹ã¿ãã¯è¡çªä¿è·ã®å²åãé«ããªã£ãŠããŸãã CentOSãšRedHatã®ããŒãžã§ã³ãæ¯èŒãããšãã¹ã¿ãã¯ã«ããªã¢ãšRELROã®å®è£ ãããŒãžã§ã³6ãã7ã«å€§å¹ ã«æ¹åãããŠããŸãããå¹³åããŠCentOSã«ã¯RHELããå€ãã®æ©èœããããŸãã äžè¬ã«ããã¹ãŠã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã¯PIEä¿è·ã«ç¹ã«æ³šæãæãå¿ èŠããããŸããããã¯ãDebian 9ãšUbuntu 18.04ãé€ããããŒã¿ã»ããã®ãã€ããªãã¡ã€ã«ã®10ïŒ æªæºã«å®è£ ãããŠããŸãã
æåŸã«ã泚æãå¿ èŠã§ãã調æ»ã¯æåã§è¡ããŸããããåæãå®è¡ããŠå®å šã§ãªãæ§æãåé¿ããã®ã«åœ¹ç«ã€å€ãã®ã»ãã¥ãªãã£ããŒã«ïŒ Lynis ã Tiger ã Hubbleãªã© ïŒããããŸãã æ®å¿µãªãããåççãªæ§æã§ã®åŒ·åãªä¿è·ã§ããããšã¯ã¹ããã€ãããªãããšãä¿èšŒããŸããã ãã®ãããéçšã¢ãã«ã«éç¹ã眮ããŠæ»æãé²æ¢ããããšã§ããªã¢ã«ã¿ã€ã ã§æ»æã確å®ã«ç£èŠããã³é²æ¢ããããšãäžå¯æ¬ ã§ãããšç¢ºä¿¡ããŠããŸãã